ITensure, Email Security, Cyber Security, Phishing, Scam

An Internet scam or phishing email utilizes deceptive information and links to trick users into voluntarily providing sensitive data.

It is most likely accomplished by including a malicious Uniform Resource Locator (URL) link. The link either directs the user to a malicious web page or contains malicious instructions itself. The goal is to execute malicious code or instructions in the user’s browser.

Spotting malicious URLs is a bit of an art. Here we’ll provide some examples of what to look for when deciding if the email or communication you’ve received is legitimate.

Practice to Look for it carefully.

Perhaps the most obvious error to spot is the misspelling. It may be an extra letter or two or just a few letters out of place.

Can you spot the difference between these two URLs?

==> www.llnkedin.com versus www.linkedin.com

What about the company name in the URL? Is it spelled correctly?

==> Microsoftnline versus Microsoftonline

Where is the company name in the URL? Tip – It is the domain name of the company. If you see .com before the company domain name, Beware! It goes to other places.

==> devopspnw.com/logon.microsoftonline.com versus login.microsoft.com/userid=joenorth

Does the company name in the email match the company domain name in the link?

Bank of America ==> BankOfAmerica@customerservice.help.com

How long is the URL? Watch out for URL with more than 100 characters. It is to confuse you and hide the actual domain.

==> http://sample.com/bank.gov/aldfjdlkfjsalkdjf;dfiawfdfsd;lfjfw;oewjflwijflijfiewf;ewo

Once you check the URL; next, pay attention to the attachment!

The malicious content will often be included as a file that launches malware, collects your information, etc.

Let’s see the name of the attachment; it looks like it’s a PDF.

For example, INV1243.pdf;

however, when you hover over the link, the URL appears as ==> https://e.pr/free/d/stuff.

What happened to the .PDF document?? Stop! Don’t Open It!

The confusing fact is legitimate companies use the same techniques. It is up to you, the recipient, to verify the sender and the content.

Be wary of providing personal or sensitive information. If you are the least bit suspicious, delete the email and contact the organization directly to confirm.


When in doubt, check with your support or email it to ask@susiechow.support for validation.
Contact Us. We are here to Help.

Susie Chow – ITensure
Call/Text: (714) 633-9454